3 ms·
BCrypt should loudly fail if more than 72 bytes are sent to its input.
by bufferoverflow 2y ago
BCrypt should loudly fail if more than 72 bytes are sent to its input.
- taurknaut 2y agoMaybe it should. Discarding the rest of the bytes works fine for passwords, though. I guess that's just not sufficient.
- pclmulqdq 2y agoIn my book, discarding entropy is a generally dumb thing to do. Passwords are usually under 72 chars, but a lot of people use concatenations of usernames and passwords in their hash to get guaranteed domain separation between users.